Trust boundary

Security

Bounded by design

The public check accepts only ordinary public HTTP and HTTPS targets. It rejects credentials, local and reserved names, private address literals, oversized responses, excessive redirects, and broad crawling. Every redirect is checked again before retrieval, and forms are never submitted.

Layered abuse protection

Cloudflare Turnstile, edge request limiting, exact durable quotas, token-protected results, asynchronous queues, retry limits, and a dead-letter path separate public requests from audit execution. Results expire automatically and can be deleted immediately.

Responsible reporting

If you believe you have found a security issue in Presence Operations, send a concise description and reproduction steps to security@presenceoperations.com. Do not access other people's results, disrupt the service, submit sensitive data, or perform destructive testing.

Scope reminder

A Presence Check is not a penetration test. Active vulnerability testing requires a separate, explicit target, method, time, and impact authorisation.